Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CDQR Parsing when Timesketch Elastic Search Not running #21

Closed
chunderstruck opened this issue Apr 13, 2018 · 4 comments
Closed

CDQR Parsing when Timesketch Elastic Search Not running #21

chunderstruck opened this issue Apr 13, 2018 · 4 comments
Assignees

Comments

@chunderstruck
Copy link

I've been running into problems where CDQR.py is throwing errors when timesketch is not running.

@chunderstruck will look into this issue and submit a pull request.

Removing uncompressed files in directory: Results/artifacts/

Process to export to ElasticSearch started
Exporting results in TimeSketch format to the ElasticSearch server
"psort.py" "-o" "timesketch" "--status_view" "linear" "--name" "bumblebee" "--index" "bumblebee" "Results/BUMBLEBEE.plaso"
ERROR: There was a problem. See details in log.
@orlikoski
Copy link
Owner

orlikoski commented Apr 13, 2018 via email

@chunderstruck
Copy link
Author

Either Elastic or Timesketch wasn't working, it was resolved when I restarted timesketch.

I've run into this issue a couple times when testing new builds...

@orlikoski
Copy link
Owner

I wonder what is causing ElasticSearch to not start up intermittently. If the RAM in Skadi is too low (less than 8GB) I know there is a chance for that to happen.

It's easy to tell if that's the issue. sudo systemctl status elasticsearch should have a message with a memory error/warning if that's the case

@orlikoski
Copy link
Owner

This doesn't appear to be an issue with the latest version. Closing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants